# Runtime secrets The canonical deployment secret is the single local file `deploy/secrets/thothii.secrets`. Copy the tracked template and protect the copy: ```sh cp deploy/secrets/thothii.secrets.example deploy/secrets/thothii.secrets chmod 600 deploy/secrets/thothii.secrets ``` The file uses strict `KEY=VALUE` lines (comments and blank lines are allowed). The supported keys are `THT_MODEL_API_KEY`, `THT_DWH_API_KEY`, `THT_VEC_API_KEY`, `THT_VEC_WRITE_API_KEY`, and the four `THT_VECTOR_*_PASSWORD` role passwords. Values must be non-empty and contain no whitespace. Do not put secrets in the root `.env`, workspace YAML, URLs, logs, or `docker compose config` output. Compose mounts the bundle read-only as `/run/secrets/thothii.secrets`. The host file must be a regular non-symlink file with mode `0600` or `0400`; Docker's normal `0444` mode is accepted only for the runtime mount beneath `/run/secrets`. The core runs as UID 10001. Verify the mount without printing its contents: ```sh docker compose run --rm core sh -c 'id && test -r /run/secrets/thothii.secrets' ``` A private CA PEM chain is not a bundle value: PEM whitespace is rejected by the strict parser. Keep it in the host or secret manager and add a reviewed Compose override that mounts it at `/run/secrets/ca-chain.pem` and sets `THT_SSL_CA` (or the adapter-specific setting). The base Compose files intentionally do not create this mount. ## Migration from separate secret files Older installations used `THT_*_SECRET_FILE` variables and one file per value. Migrate by copying each value to its bundle key, validating with `docker compose config --quiet`, and only then deleting the old files. The old variables remain a compatibility path for staged upgrades, but the documented and tested default is `THT_SECRETS_FILE=deploy/secrets/thothii.secrets`. The local-vector bootstrap rotation helper still accepts an old/new password file as its maintenance interface. Run it only with files protected by `0600`, then copy the resulting password into `THT_VECTOR_BOOTSTRAP_PASSWORD` in the bundle before restarting `vector-reconcile`/the application. The helper never prints password contents. Hosted Pi providers must use a single provider key. Compound providers (Bedrock, Azure OpenAI Responses, Cloudflare Workers AI/Gateway) fail closed until a provider-specific credential adapter is implemented.